3.1 KiB
3.1 KiB
TODO
Production Environment Variables
Cloudflare vars currently covers the non-secret values in wrangler.jsonc.
Cloudflare Secrets are currently empty, so production still needs the following
runtime values configured before deploy.
Required For Current Production Path
| Variable | How to get it | Configure as |
|---|---|---|
BETTER_AUTH_SECRET |
Generate a high-entropy production secret, for example openssl rand -base64 32. |
Cloudflare Secret |
RESEND_API_KEY |
Create or retrieve an API key from the Resend dashboard. The current mail adapter only supports MAIL_PROVIDER=resend. |
Cloudflare Secret |
CAPTCHA_SECRET_KEY |
Use the Cloudflare Turnstile Secret Key. The provided TURNSTILE_SECRET_KEY value should be stored under this variable name. |
Cloudflare Secret |
GOOGLE_CLIENT_SECRET |
Open Google Auth Platform / OAuth client settings and copy the client secret for the configured GOOGLE_CLIENT_ID. |
Cloudflare Secret |
Set with:
pnpm exec wrangler secret put BETTER_AUTH_SECRET
pnpm exec wrangler secret put RESEND_API_KEY
pnpm exec wrangler secret put CAPTCHA_SECRET_KEY
pnpm exec wrangler secret put GOOGLE_CLIENT_SECRET
Configure Only If Enabling The Feature
| Variable | When needed | How to get it |
|---|---|---|
GITHUB_CLIENT_ID |
Enable GitHub OAuth. | Create a GitHub OAuth App. |
GITHUB_CLIENT_SECRET |
Enable GitHub OAuth. | Generate it in the GitHub OAuth App settings. |
GENERIC_OAUTH_PROVIDER_ID |
Enable generic OIDC/OAuth. | Choose a provider id such as auth0, zitadel, or another stable name. |
GENERIC_OAUTH_DISCOVERY_URL |
Enable generic OIDC/OAuth. | Get the provider's .well-known/openid-configuration URL. |
GENERIC_OAUTH_CLIENT_ID |
Enable generic OIDC/OAuth. | Get it from the provider application settings. |
GENERIC_OAUTH_CLIENT_SECRET |
Enable generic OIDC/OAuth. | Get it from the provider application settings. |
PASSKEY_RP_ID |
Enable passkeys. | Use the relying-party domain, for example cfw-auth.bowong.cc or bowong.cc. |
PASSKEY_RP_NAME |
Enable passkeys. | Pick the user-facing product name, for example MixVideo. |
PASSKEY_ORIGIN |
Enable passkeys. | Use the full origin, for example https://cfw-auth.bowong.cc. |
ENABLE_JWT |
Enable Better Auth JWT plugin. | Set to true. Leave unset to disable. |
ENABLE_BEARER |
Enable Better Auth bearer plugin. | Set to true. Leave unset to disable. |
EXPO_SCHEME |
Accept Expo app origins. | Read the scheme from the Expo app config. |
SMS_PROVIDER |
Enable SMS. | Current code supports webhook or twilio. |
SMS_WEBHOOK_URL |
Use SMS_PROVIDER=webhook. |
Use the SMS provider webhook endpoint. |
TWILIO_ACCOUNT_SID |
Use SMS_PROVIDER=twilio. |
Get it from the Twilio Console. |
TWILIO_AUTH_TOKEN |
Use SMS_PROVIDER=twilio. |
Get it from the Twilio Console. |
TWILIO_FROM |
Use SMS_PROVIDER=twilio. |
Use a Twilio verified or purchased sending number. |
Needs Cleanup
| Variable | Action |
|---|---|
OAUTH_PROVIDERS |
Current source code does not read this variable. Either define its semantics and implement usage, or remove it from Env. |